Skip to content
@go-appsec

go-appsec

Application security tools written in Go. Built for pentesters, AppSec engineers, and coding agents.

Our modules focus on practical testing workflows — proxy interception, reconnaissance, out-of-band detection — designed to work standalone or together. The flagship project, toolbox, exposes these capabilities through both a CLI and an MCP server, so human operators and LLM agents can collaborate on the same session.

Repositories

go-appsec/toolbox — Collaborative application security testing between humans and agents via CLI and MCP. Proxy history, request replay, crawling, OAST, flow diffing, reflection detection — all accessible to your coding agent as MCP tools, or from the terminal as CLI commands. You handle auth and UI; the agent queries flows, mutates requests, and tests permutations.

go-appsec/interactsh-lite — Lightweight Interactsh client for out-of-band testing (OOB/OAST). Minimal dependencies, designed for embedding, but also distributed as a small CLI executable.

go-appsec/scout — Passive recon module to expand testing targets. Discovers subdomains and URLs to widen testing scope.

Pinned Loading

  1. toolbox toolbox Public

    Collaborative application security testing between humans and agents via CLI and MCP

    Go 6 1

  2. interactsh-lite interactsh-lite Public

    Lightweight rebuild of the Interactsh client from ProjectDiscovery for out-of-band testing (OOB / OAST)

    Go 1 1

  3. scout scout Public

    Passive recon golang module to expand testing targets (subdomains and urls)

    Go 1 1

Repositories

Showing 4 of 4 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…